Junglewise Threat Intelligence

CVE-2022-25904: hacksparrow safe-eval Prototype Pollution in safeEval

CVE-2022-25904 · Severity: low · CVSS 3.1 · Published 2022-12-20

Technologies: safe-eval (npm). Vendors: npm.

Executive brief

safe-eval is a Node.js library designed to execute JavaScript code in a restricted environment more safely than the standard eval() function. A vulnerability in this library allows an attacker to perform 'prototype pollution,' which can lead to the modification of global object properties. In practice, this could allow an attacker to bypass security checks, crash the application, or potentially execute unauthorized code, compromising the integrity and availability of the service.

Technical details

All versions of the safe-eval npm package (up to and including 0.4.1) are vulnerable to Prototype Pollution. The vulnerability exists because the safeEval function utilizes the Node.js 'vm' module in a way that allows executed code to access and modify the 'Object.prototype'. By passing a specially crafted string (e.g., using '__proto__') to the safeEval function, an attacker can inject or overwrite properties on the base Object prototype. This can result in application-wide side effects, including Denial of Service (DoS) or Remote Code Execution (RCE) if the polluted properties are later used in sensitive operations. As of the advisory date, there is no official patch available, and the maintainer recommends only running trusted code.

Affected products

  • hacksparrow safe-eval <= 0.4.1

Timeline

  • 2022-12-17: disclosed: Issue reported on GitHub repository
  • 2022-12-19: advisory: Snyk published advisory
  • 2022-12-20: advisory: GitHub Advisory and NVD entry published

References

Related threats